MALICIOUS — CRITICAL
Análisis de phishing y seguridad de security-click.click
security-click[.]
PhishDestroy identifies the live domain security-click.click as part of an active generic phishing campaign.
- VirusTotal
- 13/91
- Blocklists
- No stored match
- Disponibilidad
- Contenido no disponible · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
security-click.click — Contenido no disponible (HTTP 502). Tipo de estafa: Generic Phishing. Resumen de las pruebas: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 2 alerts; PhishDestroy score 89/100. Registrador: Global Domain Group.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
PhishDestroy identifies the live domain security-click.click as part of an active generic phishing campaign. The site carries a browser tab title identical to its domain name and appears to impersonate legitimate security portals, tricking users into clicking through to a drainer kit hosted on infrastructure linked to fraudulent payment capture. No evidence points to a specific brand trademark being abused at this time, but the site’s lures center on fabricated security warnings and urgent “login to secure account” prompts.
Technical indicators confirm elevated risk: Let's Encrypt issued the SSL certificate; the domain resolves to 188.114.97.3; VirusTotal detection stands at 13/95 security vendors; it was registered on April 24, 2026 through Global Domain Group LLC; and the domain appears on two blocklists maintained by OISD and Hagezi. The combination of a recent creation date, low VT coverage, and active blocklisting suggests early-stage deployment to evade takedowns.
The campaign remains active as of forensic review. Immediate recommended actions include blocking 188.114.97.3 at network perimeter devices and updating endpoint detections for the SHA-256 hashes associated with this domain, which can be extracted from the URL path captured in proxy logs. While the overall risk is elevated, the low VT score and narrow blocklist footprint indicate that most protective stacks have not yet cataloged this indicator. Users should avoid visiting security-click.click and report any accidental interactions to their security teams for credential reset and endpoint scans.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | security-click.click |
malicious | Sinkholed |
| DNS4EU | security-click.click |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 3 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 100 % de confianzaNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100 % de confianzaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaAnálisis de VirusTotal
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.